==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [227968 2013-03-27] (Qualcomm Atheros Commnucations) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-02] (AVAST Software)
S4 Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [229376 2006-02-28] (Apple Computer, Inc.) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100752 2013-04-10] (ELAN Microelectronics Corp.)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2013-12-27] (Macrovision Europe Ltd.) [File not signed]
S2 Globe Tattoo Broadband. RunOuc; C:\Program Files (x86)\Globe Tattoo Broadband\UpdateDog\ouc.exe [655712 2014-03-22] ()
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
S3 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-05-07] (Intel Corporation)
R2 KMService; C:\Windows\SysWOW64\srvany.exe [8192 2010-06-15] () [File not signed]
R3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [279848 2007-06-27] (Nero AG)
S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1045376 2016-01-08] (Enigma Software Group USA, LLC.)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [15440 2012-07-25] (Microsoft Corporation)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe
S2 UxTuneUp; %SystemRoot%\System32\uxtuneup.dll ===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-02] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-21] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-02] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-02] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1055560 2015-12-02] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [451040 2015-12-21] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-02] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-02] (AVAST Software)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-03-27] (Qualcomm Atheros)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3295984 2012-07-25] (Broadcom Corporation)
R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15920 2016-01-08] (Enigma Software Group USA, LLC.)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2016-01-08] ()
S3 huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [223744 2014-03-22] (Huawei Technologies Co., Ltd.)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99800 2013-05-07] (Intel Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31984 2013-03-06] (Synaptics Incorporated)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [34216 2012-07-25] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [258288 2012-07-25] (Microsoft Corporation)
S1 F06DEFF2-5B9C-490D-910F-35D3A91196222; ??\C:\Program Files (x86)\Movies Toolbar\Datamngr\x64\setmgrc2.cfg
S2 VBoxAswDrv; ??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-16 01:10 - 2016-01-16 01:10 - 00035403 _____ C:\Users\User\Downloads\FRST.txt
2016-01-16 01:09 - 2016-01-16 01:10 - 00000000 ____D C:\FRST
2016-01-16 01:05 - 2016-01-16 01:08 - 02370560 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
2016-01-16 01:01 - 2016-01-16 01:01 - 26640936 _____ C:\Users\User\Downloads[ENG] 160112 BOMB- Hide and seek with JM, V, JK (#1).mp4.crdownload
2016-01-16 00:55 - 2016-01-16 00:55 - 31001734 _____ C:\Users\User\Downloads[ENG] 160108 BOMB- BTS 5th Win @ real last day of ‘RUN’.mp4.crdownload
2016-01-16 00:54 - 2016-01-16 01:02 - 23067068 _____ C:\Users\User\Downloads[ENG] 160104 EPISODE- BTS ‘The Most Beautiful Moment In Life Pt.2’ Jacket Shooting.mp4
2016-01-16 00:54 - 2016-01-16 00:58 - 10159366 _____ C:\Users\User\Downloads[ENG] 151211 BOMB- Inkigayo Special MC debut Rap Monster.mp4
2016-01-16 00:54 - 2016-01-16 00:55 - 05656614 _____ C:\Users\User\Downloads[ENG] 151105 V.mp4
2016-01-16 00:53 - 2016-01-16 00:53 - 03143347 _____ C:\Users\User\Downloads[ENG] 151222 BOMB- 2 brushes for Jung Kook s teeth.mp4
2016-01-16 00:49 - 2016-01-16 00:51 - 16899508 _____ C:\Users\User\Downloads[ENG] 151231 BOMB- Happy new year 2016!.mp4
2016-01-16 00:49 - 2016-01-16 00:51 - 14599643 _____ C:\Users\User\Downloads[ENG] 151214 BOMB- Jimin s self camera (RUN 151204 ver.).mp4
2016-01-16 00:49 - 2016-01-16 00:49 - 04109942 _____ C:\Users\User\Downloads[ENG] 151230 BOMB- sleepy j-hope.mp4
2016-01-16 00:45 - 2016-01-16 00:47 - 03351475 _____ C:\Users\User\Downloads[ENG] 151223 BOMB- Sleeping Baby bothered with Jin.mp4
2016-01-16 00:44 - 2016-01-16 00:47 - 09470373 _____ C:\Users\User\Downloads[ENG] 151216 BOMB- Playing the rhythm game (…and V’s making a song).mp4
2016-01-16 00:40 - 2016-01-16 00:47 - 56683507 _____ C:\Users\User\Downloads[ENG] 151211 EPISODE- BTS won 1st place at Music Bank with ‘RUN’.mp4
2016-01-16 00:38 - 2016-01-16 00:40 - 10918454 _____ C:\Users\User\Downloads[ENG] 151207 BOMB- Music bank special MC V.mp4
2016-01-16 00:29 - 2016-01-16 00:39 - 31407910 _____ C:\Users\User\Downloads[ENG] 160114 BOMB- Hide and seek with JM, V, JK (#2).mp4
2016-01-16 00:15 - 2016-01-16 00:18 - 13787063 _____ C:\Users\User\Downloads\151231 가요대제전 방탄소년단 perfect man JIMIN focus.mp4
2016-01-08 02:58 - 2016-01-08 02:58 - 00003314 _____ C:\Windows\System32\Tasks\SpyHunter4Startup
2016-01-08 02:58 - 2016-01-08 02:58 - 00000000 ____D C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpyHunter
2016-01-08 02:58 - 2016-01-08 02:58 - 00000000 ____D C:\Users\User\AppData\Roaming\Enigma Software Group
2016-01-08 02:58 - 2016-01-08 02:58 - 00000000 _____ C:\autoexec.bat
2016-01-08 02:55 - 2016-01-08 02:55 - 00022704 _____ C:\Windows\system32\Drivers\EsgScanner.sys
2016-01-08 02:54 - 2016-01-08 02:54 - 00000000 ____D C:\Program Files\Enigma Software Group
2016-01-07 20:35 - 2016-01-07 20:35 - 00000131 _____ C:\Windows\system32\netcfg-4175015.txt
2016-01-07 20:33 - 2016-01-07 20:34 - 00000156 _____ C:\Windows\system32\netcfg-4066921.txt
2016-01-07 20:33 - 2016-01-07 20:33 - 00000156 _____ C:\Windows\system32\netcfg-4015718.txt
2016-01-07 20:32 - 2016-01-07 20:32 - 00000156 _____ C:\Windows\system32\netcfg-3975843.txt
2016-01-07 20:21 - 2016-01-07 20:21 - 00000131 _____ C:\Windows\system32\netcfg-3347187.txt
2016-01-07 20:20 - 2016-01-07 20:20 - 00000156 _____ C:\Windows\system32\netcfg-3275703.txt
2016-01-07 20:15 - 2016-01-07 20:34 - 00000375 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2016-01-07 20:15 - 2016-01-07 20:15 - 00000156 _____ C:\Windows\system32\netcfg-2934468.txt
2016-01-07 20:13 - 2016-01-07 20:14 - 00000156 _____ C:\Windows\system32\netcfg-2853828.txt
2016-01-07 19:57 - 2016-01-07 19:57 - 00000131 _____ C:\Windows\system32\netcfg-1876000.txt
2015-12-26 21:11 - 2015-12-26 21:11 - 00000000 ____D C:\Users\User\Documents\Avatar
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-01-16 01:10 - 2012-07-25 21:37 - 00000000 ____D C:\Windows
2016-01-16 00:49 - 2014-11-10 01:18 - 00000916 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-01-16 00:48 - 2014-11-10 01:22 - 00002189 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-01-16 00:21 - 2013-12-27 09:49 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-01-15 17:51 - 2013-12-27 09:09 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3497284572-2413806544-361628044-1001
2016-01-15 16:52 - 2014-11-10 01:18 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-01-12 22:42 - 2013-12-27 09:52 - 00000000 ____D C:\Users\User\AppData\Roaming\vlc
2016-01-12 22:07 - 2013-12-27 20:16 - 00000000 ____D C:\Users\User\AppData\Roaming\dvdcss
2016-01-12 17:57 - 2013-12-27 21:12 - 00000000 ____D C:\Users\User\AppData\Local\CrashDumps
2016-01-11 19:04 - 2014-01-11 15:14 - 00004184 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-01-10 21:07 - 2013-12-27 09:52 - 00000000 ____D C:\Users\User\AppData\Roaming\Winamp
2016-01-08 17:37 - 2013-12-27 09:37 - 00000000 ____D C:\Users\User\Documents\Youcam
2016-01-08 15:38 - 2015-05-26 17:39 - 00000000 ____D C:\Windows\Minidump
2016-01-08 15:38 - 2014-12-23 20:10 - 00000000 ____D C:\Users\User\AppData\Roaming\uTorrent
2016-01-08 15:38 - 2012-07-25 21:37 - 00000000 ____D C:\Windows\Inf
2016-01-08 15:21 - 2012-07-26 00:12 - 00000000 ____D C:\Windows\system32\NDF
2016-01-08 14:46 - 2012-07-25 23:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-01-08 09:57 - 2013-12-27 09:48 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-01-08 09:57 - 2013-12-27 09:48 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-01-08 09:57 - 2013-12-27 09:03 - 00001430 _____ C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-01-07 20:24 - 2012-07-25 23:28 - 00803370 _____ C:\Windows\system32\PerfStringBackup.INI
2015-12-31 15:06 - 2013-12-27 13:57 - 00000000 ____D C:\Users\User\AppData\Roaming\Atheros
2015-12-31 15:06 - 2013-12-27 13:52 - 00000000 ____D C:\Users\User\Documents\Bluetooth Folder
2015-12-27 23:58 - 2013-12-27 09:40 - 00000000 ____D C:\Users\User\AppData\Local\Microsoft Help
2015-12-26 21:26 - 2012-07-26 00:12 - 00000000 ____D C:\Windows\ModemLogs
2015-12-26 21:20 - 2015-01-01 01:59 - 00000000 ____D C:\Users\User\Documents\done
2015-12-21 23:25 - 2013-12-27 09:45 - 00451040 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2015-12-21 23:25 - 2013-12-27 09:45 - 00097648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswmonflt.sys
Some files in TEMP:
C:\Users\User\AppData\Local\Temp\cdo1922773328.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-01-10 17:42
==================== End of FRST.txt =========